Record summary

CVE-2023-27290 has a selected CVSS score of 9.1 (critical); EIP currently links 1 catalogued exploit.

Description

Docker based datastores for IBM Instana (IBM Observability with Instana 239-0 through 239-2, 241-0 through 241-2, and 243-0) do not currently require authentication. Due to this, an attacker within the network could access the datastores with read/write access. IBM X-Force ID: 248737.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 5, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Observability with Instana

Browse IBM / Observability with Instana

Default status: unaffected

CVE List239-0 to < 239-2affected
241-0 to < 241-2affected
243-0affected

Proofs of concept

1

Catalogued exploits

ExploitDBDocker based datastores for IBM Instana 241-2 243-0 - No AuthenticationExploitDB exploitby Shahid Parvez (zippon)Not analyzed1 file
ExploitDB

PoC details

References

4